Senior Consultant/Manager | Cyber Operate | Cyber Performance Management Specialist |KSA
Deloitte Middle East · Riyadh, Saudi Arabia · 1d ago
Senior Consultant/Manager | Cyber Operate | Cyber Performance Management Specialist |KSA
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.
Our Purpose
Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most—for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Senior Consultant/Manager, you will demonstrate and develop your capabilities in the following areas
Design the performance framework
·Design the cybersecurity performance management framework: objectives, KPIs, KRIs, SLAs, targets and thresholds, data sources, owners, collection frequency and reporting lines
·Write and maintain the supporting methodology, procedures and SOPs for data collection, validation, calculation, review and sign-off
·Align metrics with the cybersecurity strategy, NCA ECC requirements and NIST CSF 2.0, so they measure outcomes and risk reduction, not just activity
·Review and refine metrics regularly, retiring ones that no longer drive decisions
Define success metrics for cybersecurity functions and roles
·Define clear success metrics for each cybersecurity function and its roles, agreed with each domain lead, for example:
oStrategy and architecture: roadmap milestones delivered, maturity uplift, designs reviewed before go-live, architecture exceptions open
oVulnerability management and penetration testing: scan coverage, remediation within SLA, ageing of critical vulnerabilities, retest closure rate, repeat findings
oApplication and OT security: applications onboarded to secure SDLC, critical code findings fixed before release, OT assets inventoried and monitored, OTCC gaps closed
oRisk and compliance: risks assessed and treated on time, overdue treatment plans, NCA ECC compliance score and trend, audit findings closed
oThird-party and supply chain: critical suppliers assessed before onboarding, reassessments on time, high-risk supplier findings open, critical suppliers with tested exit and continuity plans, fourth-party and concentration risks identified, supplier incidents and notification times
oGovernance and awareness: policies current and approved, committee actions closed, training completion, phishing simulation trends
·Define how each metric is measured: formula, data source, baseline, target, frequency, owner and evidence, so results are consistent and can be audited
·Set measures at three levels: programme outcomes, function performance, and role and team contribution, and link them so leaders can see how individual work adds up to programme results
·Support domain leads in using the metrics for team objectives and performance reviews
Work with the Governance team
·Work closely with the Governance & PMO team to understand governance implementation requirements: approved policies, standards, roles and RACI, committee decisions and NCA obligations
·Turn those requirements into measurable indicators, such as policy implementation and adherence, SOP compliance, role coverage, and committee decision and action closure rates
·Track whether governance decisions are actually implemented on the ground, and report gaps back to the Governance team and steering committee
·Provide performance evidence for ISMS management reviews and NCA compliance reporting
Measure services and the programme
·Track the service levels and performance of managed security services and key security vendors, and run monthly service reviews with clear actions
·Track programme delivery and benefits against plan, with the PMO
·Measure cybersecurity maturity and NCA compliance trends over time, with the Strategy and Compliance teams
Build dashboards and reports
·Build and maintain dashboards and scorecards for the CISO, steering committee and board (e.g. Power BI), with drill-down by function, team and role
·Automate data collection from security tools, GRC, TPRM and ticketing platforms where possible, so reports are timely and consistent
·Produce monthly and quarterly performance reports that explain what changed, why, and what needs to happen next, written in plain language for executives
Drive improvement
·Spot negative trends and missed targets early, analyse root causes with the owners, and agree improvement actions
·Track improvement actions to closure and show their effect in later reporting
·Validate data quality and challenge figures that don't add up
Leadership Capabilities:
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
·Years of experience: 4-8 total professional years.
·Bachelor's in IT, cybersecurity, business, data analytics or a related field
·Has designed or run a KPI/KRI or SLA performance framework covering multiple functions (Senior); has built performance dashboards and reports (Mid)
·Understanding of cybersecurity domains, including third-party and supply chain risk, enough to define meaningful metrics for each function
·Strong data skills: Excel and Power BI (or Tableau), with data modelling
·Experience managing SLAs and service performance (ITIL)
·Clear, concise written English for executive reporting
·SQL or Python for data extraction and automation
·Experience linking organisational KPIs to team and individual objectives
·Experience with managed security services (MSSP) contracts and service reviews
·Experience with maturity assessment models
·Knowledge of ISO/IEC 27004 and NIST SP 800-55
·Arabic is a plus
·At least one preferred: ITIL 4, CISM, Microsoft Power BI Data Analyst (PL-300). Also valued: PMP, CGEIT, COBIT.
·NIST CSF 2.0 · NIST SP 800-55 (performance measurement) · ISO/IEC 27004 · NCA ECC-2:2024 · ITIL 4 · COBIT 2019 · Balanced Scorecard